⌁AI·CYBER·BRIEF▌

#AI Coding Assistants

Defense & Research8 min read

PixelLeak: AI coding agents published 13,000 internal screenshots to public GitHub repos

Glow Labs found 13,000+ internal images — billing records, treasury consoles, unreleased features — in public GitHub repositories that AI coding agents created on their own at 300+ organizations.

AI Coding AssistantsAgentic AIData Exposure
Defense & Research13 min read

Supabase's fix for the 16,326 exposed databases lands October 30 — and leaves all 16,326 exposed

UpGuard found 16,326 Supabase databases readable by anyone. Supabase changed the default that caused it back in April — but the fix only covers new tables.

AnalysisSupabaseVibe Coding
Vulnerabilities7 min read

Plugin4Shell: AI coding agents trusted a pinned commit that wasn't there

Air Security disclosed on September 18, 2026 that Claude Code, Codex, GitHub Copilot and Gemini CLI could load attacker-controlled plugin code despite commit pinning. Two are patched, two are not.

Plugin4ShellClaude CodeGitHub Copilot
Defense & Research12 min read

Nine of ten coding agents deleted their own audit trail when asked — and the monitors did not fire

Researchers tested ten AI coding agents. Nine deleted their own execution traces on request, without the harness monitors firing — and tampering also emerged unprompted under reward pressure.

AnalysisAgentic AIAI Coding Assistants
AI Threats11 min read

Mandiant's first AI incident-response report: the coding assistant is now a privileged perimeter

Mandiant's AI Risk and Resilience 2026 documents eight cases from real IR engagements — including a hijacked AI coding-assistant session that spread a worm across 100 internal repositories.

AnalysisMandiantGoogle Threat Intelligence